Strong customer authentication requires two independent factors from the categories knowledge, possession and inherence before an online payment is approved. 3-D Secure is the protocol that carries this for card payments. These controls stop impersonation, but not payments you approve after being deceived. A chargeback is a card scheme agreement with a limited window, not a legal right.
On this page
- What SCA is
- Authentication using two or more independent elements from knowledge, possession and inherenceSource 1
- When it applies
- Accessing an account online, initiating an electronic payment, or any remote action implying fraud riskSource 2
- Chargeback window
- Usually around 120 days to raise oneSource 5
- APP fraud reimbursement cap
- £85,000, for UK Faster Payments and CHAPS transfersSource 7
Two different problems
Payment security covers two problems that look similar and are not.
The first is impersonation: somebody else uses your card or account. Banking rules and card networks have spent years reducing this, and they have been reasonably successful.
The second is deception: you make the payment yourself, having been convinced to. No authentication step catches this, because the authentication works exactly as designed.
Understanding which is which tells you what protection actually applies afterwards.
Strong customer authentication
In the United Kingdom, strong customer authentication is defined in law as "authentication based on the use of two or more elements that are independent, in that the breach of one element does not compromise the reliability of any other element"1. Those elements must fall into two or more of three named categories: knowledge, something known only by the payment service user; possession, something held only by that user; and inherence, something inherent to that user1.
| Category | Typical example |
|---|---|
| Knowledge | A password or PIN |
| Possession | A registered phone or a card reader |
| Inherence | A fingerprint or face scan |
A payment service provider must apply it "where a payment service user— (a) accesses its payment account online... (b) initiates an electronic payment transaction; or (c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses"2.
For remote payments there is an extra requirement: the authentication must include "elements which dynamically link the transaction to a specific amount and a specific payee"2. In practice this is why the approval prompt in a banking app shows the amount and the merchant. Reading that screen is the single most useful security habit available to a consumer.
The FCA summarises the purpose for consumers: the rules "aim to reduce the risk of a fraudster pretending to be you to steal your money"4. The rules took effect on 14 September 20193.
3-D Secure, and why some payments are not challenged
For card payments, the protocol carrying this is EMV 3-D Secure. EMVCo describes it as helping "payment card issuers and merchants around the world prevent card-not-present (CNP) fraud and increase the security of e-commerce payments" by exchanging data between merchant and issuer about "the transaction, payment method and device"6.
Not every payment produces a challenge. EMVCo notes that "For many transactions, this means consumers simply click 'Buy' and the payment is approved", with further authentication requested only for "higher-risk transactions"6.
The European Banking Authority recognised in June 2019 that protocols such as EMV 3DS provide a means to support strong customer authentication, by enabling two-factor authentication through methods including a one-time passcode, knowledge-based questions or biometrics6.
A payment going through without a prompt is therefore normal. It is not evidence that a site has bypassed anything.
Phishing and fake cashier pages
The second problem is social, and the patterns are well documented. The National Cyber Security Centre lists the signals that appear in most scam messages8.
- Authority. "Is the message claiming to be from someone official? For example, your bank, doctor, a solicitor, or a government department."
- Urgency. "Are you told you have a limited time to respond (such as 'within 24 hours' or 'immediately')?"
- Emotion. "Does the message make you panic, fearful, hopeful or curious?"
- Scarcity. "Is the message offering something in short supply, like concert tickets, money or a cure for medical conditions?"
- Current events. "Are you expecting to see a message like this?"
The NCSC's advice when something looks wrong is to "contact the organisation directly" and not to "use the numbers or address in the message – use the details from their official website"8. It also notes that legitimate organisations "will never ask you to supply personal information via email, or call and ask you to confirm your bank account details"8.
A fake cashier page is the same attack applied to a payment screen. The page is a copy, the payment is real, and it goes somewhere else. Clone sites are covered in more detail in how to spot unsafe gambling sites.
Bank fraud controls and reimbursement
Where a transfer is made under deception, a separate route exists in the United Kingdom.
The Payment Systems Regulator describes authorised push payment fraud as happening "when you're tricked into sending money to a fraudster via bank transfer"7. Since 7 October 2024 the reimbursement requirement has applied to payments made on or after that date, covering UK bank transfers over Faster Payments and CHAPS, with a maximum claim of £85,0007.
Claims should be reported "as soon as possible, and within 13 months of making the fraudulent payment", with reimbursement due within five business days, or 35 business days where a firm needs more information7.
The scheme excludes card, cash and cheque payments, which have their own protections, and does not cover civil disputes7.
What a chargeback can and cannot do
Chargeback is often described as a guarantee. It is not.
MoneyHelper is direct: "Chargeback isn't legal protection like section 75, which applies in the UK. It's an agreement Visa, Mastercard and American Express have signed up to"5.
The Financial Ombudsman Service describes it as letting you "challenge and 'claw back' payments made using a debit or credit card", with each scheme setting its own rules, and notes you "usually have around 120 days to raise a chargeback about goods or services", though "Time limits might be longer or shorter depending on the circumstances"9.
| Chargeback | Section 75 | |
|---|---|---|
| Basis | Card scheme agreement5 | Statutory protection9 |
| Cards covered | Debit, credit and prepaid5 | Credit card only9 |
| Value limits | None stated | Cash price over £100 and not more than £30,0009 |
| Typical window | Around 120 days9 | Longer, set by the Act |
What neither route is designed to do is unwind a gambling loss. A completed wager is not a faulty good, and attempting to reverse it as one is a route to a closed account rather than a refund.
Storing as little as possible
The final layer is reducing what there is to steal.
The PCI Security Standards Council sets the data security standard that applies to "entities that store, process or transmit payment account data"10. Compliance is enforced by payment brands and acquirers rather than by the Council itself10.
From a consumer's side the equivalent principle is the same one, applied to your own footprint.
- Keep balances where they are protected. The FSCS states that it "can't protect the money you have with e-money institutions and payment providers"11.
- Remove stored cards from accounts you are not using.
- Use a unique password per site and enable the strongest authentication offered.
- Read the amount and payee on every approval prompt, since dynamic linking puts them there for exactly that reason2.
How the methods themselves differ is covered in casino payment methods compared, with method-by-method detail in the payments section.
- KYC (know your customer)
- Checks a gambling operator carries out to confirm a customer's identity and age, and sometimes their source of funds. Some regulators, such as Great Britain's Gambling Commission, require age and identity to be verified before a customer gambles.
If a payment has gone wrong, contact your bank using the details on its official website rather than any number sent to you.